Found by design-dev's impeccable run and confirmed at source. Python-Markdown passes raw HTML through, and doc.html and booth.html render the result |safe. A <script> in any session's .md ran on the Booth's origin, and a contract that quoted <pre> opened a real one and swallowed the rest of the doc. Operator ruling: escape raw HTML (not an allowlist). - render_doc deregisters Python-Markdown's block and inline HTML processors, so raw HTML reaches the serializer as text and is escaped there. Fenced and inline code are unchanged. - Every link href in a doc goes through links.is_safe_href after browser-style decoding. Python-Markdown keeps character references in attributes, so `javascript:` reached the browser as `javascript:`. - is_safe_href reads a backslash as a slash, as a browser does in an http(s) URL: `/\evil.test` is `//evil.test`. This also closes the hole on the link board. - A render that raises falls back to raw text, which the template escapes. Two of 19 live .md files render differently. One is a contract losing the quoted <pre> that swallowed it. The other is links.md, which renders as a board, not through render_doc. heid bug-hunt panel (4/4): the core claim held. Its two concrete edges (the backslash twin, the unbounded render) are fixed here. Table tests/mutations/doc_html.toml: 9/9 proved. Suite 951 -> 975.
39 lines
2.3 KiB
Markdown
39 lines
2.3 KiB
Markdown
# 2026-09-28 — A posted doc could run script on the Booth's origin
|
|
|
|
**Found by design-dev's impeccable run** (the whole-surface audit Prime asked
|
|
for, report booth `booth-antislop`), confirmed at source by booth-dev:
|
|
Python-Markdown passes raw HTML through and `doc.html` / `booth.html` render it
|
|
`|safe`. Any session's `.md` could carry a `<script>`; a contract that merely
|
|
QUOTED `<pre>` opened a real one and swallowed the rest of the doc.
|
|
|
|
**Operator ruling (Prime, in this session: "A"; and in design-dev's): ESCAPE
|
|
raw HTML, not an allowlist** — the live docs that carry tags mean the literal
|
|
tag, and an allowlist would still turn a quoted `<pre>` into a real one.
|
|
Measured before shipping: 2 of 19 live `.md` files render differently; one is
|
|
`booth-redesign/03-u1-item-record.contract.md` losing exactly the swallowing
|
|
`<pre>`, the other is `links/links.md`, which renders as a board and never
|
|
through `render_doc`.
|
|
|
|
**Found while fixing it, same class:** markdown link hrefs were never checked,
|
|
and Python-Markdown keeps character references in attributes, so
|
|
`[x](javascript:...)` reached the browser as `javascript:`. Every doc href
|
|
now goes through `links.is_safe_href` after browser-style decoding
|
|
(`_browser_href`). mailto autolinks lose their href as a result; accepted.
|
|
|
|
**The heid panel (4/4, thread `01M3MFG07JCAJTQXRBC1GKS2FG`) said the core
|
|
claim holds** and found its edges: `/\evil.test` passed `is_safe_href` as a
|
|
relative path although a browser reads it as `//evil.test` (fixed in the ONE
|
|
predicate, so the board is closed too); no bound around the render (fixed:
|
|
a raising render falls back to escaped raw text, which also covers a markdown
|
|
upgrade renaming the deregistered processors — the tests would go red on that
|
|
upgrade). Declined: emphasis still applying inside quoted HTML (`**x**` in a
|
|
quoted attribute renders bold) — that is prose getting markdown; quote in a
|
|
code span for byte-literal. Accepted: `img@src` unguarded (inert in current
|
|
browsers; data: images are legitimate), `html.unescape` as a superset of
|
|
attribute decoding (over-refuses at worst).
|
|
|
|
**Guards not claimed as falsifiers:** the tab/CR/LF drop and C0 trim in
|
|
`_browser_href`, because Python 3.13's urlsplit does the same; the
|
|
AMP_SUBSTITUTE restore, reachable only through automail (always `mailto:`).
|
|
Table: `tests/mutations/doc_html.toml`, 9/9 proved.
|